Tampilkan postingan dengan label business. Tampilkan semua postingan
Tampilkan postingan dengan label business. Tampilkan semua postingan

Jumat, 09 Maret 2007

Sourcefire Is Now FIRE

With the appearance of Sourcefire as FIRE on the NASDAQ, I'd like to congratulate Marty Roesch and friends for bringing their company to the public market. I can't think of another company where one can chat with the CTO and founder in IRC.

Several of you have asked for my thoughts on this development. I posted Thoughts on Sourcefire IPO in October and I don't see anything that changes those opinions. Since then, I've been working with several customers, including one who brought me to a Sourcefire sales demo. At that demo, and in meetings with other customers, the ability for a detection product to act like a Security Event Management / Security Information-Incident Management (SEM/SIM) solution repeatedly arose. Sourcefire's products can feed a SEM/SIM but their Defense Center is not a SEM/SIM.

This is a big hurdle for Sourcefire. I don't see customers buying a Sourcefire intrusion sensor, and RNA, and a Defense Center, and then paying more money for a SEM/SIM. Instead I see customers adding an IDS module to their router or switch and feeding everything into MARS. (You know how much I love MARS, so this is not something I want to see happen. It's just what is happening.)

I think Q1 Labs has the right idea, even though I don't have hands-on time with their gear (yet). Products which are a SEM/SIM and a network management platform are going to be one of the few network-centric security products to not be collapsed into switches. (Network forensic appliances, due to their storage requirements, will also not collapse into switches.) If Sourcefire moves up the food chain into the Q1 Labs model, then I think they have a future as an independent security vendor. If they concentrate on their IDS/IPS solution they will eventually be purchased by a bigger security company like Cisco or a competitor.

Jumat, 02 Februari 2007

Single-Digit Security Service Providers

Yesterday I learned that more friends of mine from Foundstone have departed to start their own companies. I could probably list a dozen such companies with whom I do work, from whom I get leads, or to whom I pass leads. It seems this is a really popular way for security specialists to do work they enjoy without the burden of corporate management.

I think clients like this approach because they always interact directly with the people doing the work. They can target specialists and only bring in the people they need. When I am hired for a project that extends beyond network-centric monitoring, response, and/or forensics, I call on one or more friends I trust. For example, one client needs help with monitoring, infrastructure, and applications, so I am driving to the client with the best guys I know for each subject.

I wonder if it might be useful for all of us "single-digit security service providers" (i.e., those of us with less than ten employees) to meet, perhaps at Black Hat USA? So many people asked if I was attending Black Hat last year, but I didn't make it. This year I think I will attend, and it might be cool for all of the security small business owners to meet and share war stories and capabilities. I'd like to expand my list of trusted colleagues, but I usually only feel comfortable recommending another person after I've met them and hopefully seen what skills they offer. This is related to my personal LinkedIn policy.

While I know a lot of people at bigger companies, I'm never really going to call on a large company for help unless the project is beyond what I could do with a small team. So, please don't be offended if you want to attend this meeting but work for a big consulting firm or defense contractor. Your company doesn't need any help from my company, believe me!

If there's interest in large companies looking to subcontract work to small companies, I think we can talk about arranging a second meeting for that sort of social networking. I do that too and so do my friends. If you work at a large company and want to meet potential subcontractors, also please email me and we'll set up a second meeting to accommodate those interests.

If either of these meetings at Black Hat sound like a good idea, please comment here and/or email taosecurity [at] gmail [dot] com. Thank you.

Selasa, 19 Desember 2006

Thoughts on Check Point Acquisition of NFR

Earlier this year I covered Check Point's attempt to purchase Sourcefire. Well, Check Point bought another vendor -- NFR -- for $20 million. Talk about market valuation; Sourcefire's sale price was $225 million. NFR is also down to 22 employees, according to the press release. Although the FAQ says

Check Point intends to continue to sell, support, and develop an independent NFR Security product line.

I doubt that will last. It doesn't make sense to buy the technology but not integrate it into Check Point's firewalls, and then discard the separate box.

At this point it seems we're left with the following IDS/IPS vendors:

Let's see how that relates to the idea that all network security functions will collapse to switches. The first four sell switches, so I expect them to lead that drive. The fifth (ISS) is owned by IBM, who is more interested in services these days. I expect IBM will discontinue or sell off that product line, following Symantec's lead, to focus on services.

I don't think McAfee's prospects are good. I think Microsoft will eventually crowd out the anti-virus/anti-malware/anti-spyware/NAC/host defense market. All host-centric security will collapse into the operating system. That knocks out a huge chunk of McAfee's product line. This is really going out on a limb, but I could see McAfee being sold off in pieces, with Microsoft acquiring host-centric assets, Cisco or another switch vendor buying Intrushield, and IBM acquiring the services part.

Where does this leave Sourcefire? If they eventually do go public, I think they will still end up being purchased by someone -- maybe Cisco. At some point Cisco will realize their IDS is not that great, and they will buy better technology. The Feds will see Cisco as a perfectly acceptable suitor and will approve the deal.

Returning to Check Point, they will probably be acquired by a switch vendor at some point too.

Did I miss anyone? I don't count all the vendors repackaging Snort.

Selasa, 07 November 2006

Bejtlich Cited in Sourcefire IPO Story

Bill Brenner published this quote in his story Sourcefire IPO could fuel Snort, users say:

The infrastructure to support Snort isn't cheap and Sourcefire isn't flush with cash, said Richard Bejtlich, founder of the Washington, D.C.-based consultancy Tao Security. "The money to keep Snort thriving has to come from somewhere, and an IPO could give Snort more legs," he said.

I based this thought on the following from Sourcefire's S-1, listed under Risks Related to Our Business:

We have incurred operating losses each year since our inception in 2001. Our net loss was approximately $10.5 million for the year ended December 31, 2004, $5.5 million for the year ended December 31, 2005 and $2.9 million for the nine months ended September 30, 2006. Our accumulated deficit as of September 30, 2006 is approximately $40.3 million.

It looks like Sourcefire's losses are narrowing, which points to future profitability. My point is that development of Snort and associated software (RNA, etc.) takes significant resources. While it might not be that difficult to fork Snort and maintain its code base, adding significant features and developing complex rules would be extremely tough for a noncommercial enterprise to sustain.

Jumat, 27 Oktober 2006

Thoughts on Sourcefire IPO

In the spirit of not trying to repeat what everyone else blogs, I'll keep this post on the Sourcefire IPO brief. The must-read post belongs to Mike Rothman -- great work Mike.

I'm excited by this development. I'll probably even buy some Sourcefire stock, just so I can attend the shareholders meeting. I've never owned stock in a friend's company, so this would be novel enough to justify the purchase.

However, in the long term I expect Sourcefire to be acquired anyway. I stand by my ideas that all network security functions will collapse to the switch, something Richard Stiennon called Secure Network Fabric. This means Sourcefire either needs to sell switches that compete with Cisco (unlikely) or be bought by Cisco (possibly) or a Cisco competitor (probably).

Customers are growing increasingly disillusioned with buying more and more point products. If they simply perceive that existing equipment (switches and routers) can be upgraded to implement new security features, they'll pursue that path. Alternatively, they'll include the new functionality in the next switch/router technology refresh. At the most I see a "switch plus one" model, where no more than one stand-alone security device will support the core switch/router infrastructure. Everything that a switch/router cannot perform, security-wise, will be expected of the "firewall," which Marcus Ranum originally defined as a security system and not simply a product.

At some point a majority of hosts will be virtualized, and many network and host security measures will be performed by the hypervisor anyway.

Rabu, 25 Oktober 2006

Counterpane Bought: Investors Relax

Eighteen months after MCI bought MSSP NetSec, another telecom has bought another MSSP. This time, BT bought Counterpane. I guessed that Counterpane was desperate. At least the investors who poured four rounds of venture capital into Counterpane can realize some sort of return. The announcement concluded with this statement:

As at 31 December 2004 the audited gross assets of the business were $6.8m.

That doesn't sound very promising.

I expect a good amount of reorganization and removal of personnel. BT will want the low-level analysts to stay, but some will probably leave. The middle-managers will want to stay, but BT will send them packing. Since Counterpane's brain trust has largely disappeared, they only need to keep Bruce Schneier as their "visibility guy" or "mantlepiece."

Good luck to them -- I imagine they will be morphed into protecting BT's cloud.

Update: After reading helpful comments and stories like this, it appears Counterpane's investors took a big loss if the company sold for around $40 million. According to the Counterpane series C VC funding press release:

The Goldman Sachs Group, Inc., and Morgan Stanley Dean Witter Private Equity, who all invested further in this round, bringing the total capital raised by Counterpane to $58 million.

Then add $20 million of series D VC funding and the total is $78 million. It looks like the "return on investment" I mentioned earlier was very negative.

Finally:

Counterpane will run as a standalone operation until April 2007, before being integrated in to BT's Professional Services organisation.

Rabu, 20 September 2006

Does SecureWorks-LURHQ Count as Consolidation?

I think it does. Managed network security services is one arena where size is always a factor, and bigger is usually better. With more employees you have more analysts per shift. You have more customers, so you see more of the Internet. With enough customers your view of the Internet begins to resemble a statistically significant sample, from which you can make inferences about the health of the global network.

I thought this Dark Reading story on the merger (the new company will be called SecureWorks -- no more "how do I say LURHQ?") had an interesting quote:

But all of this doesn't mean IBM-ISS isn't on SecureWorks' radar: Prince says SecureWorks' main competitors on the enterprise side are Symantec, VeriSign, and "now IBM." On the commercial side, it will be local telcos and other service providers, he says.

Where is Counterpane? They must be desperate for a buyer. I expect to see more MSSPs combining to form Voltron as time progresses.

Rabu, 23 Agustus 2006

More Security Consolidation

By now you've heard that IBM is buying ISS for $1.3 billion. Wow. This is much larger than the purchases of Foundstone, @Stake and Guardent in 2004 by McAfee, Symantec, and VeriSign (respectively). Remember also in early 2005 that NetSec was bought by MCI, who was then bought by Verizon.

IBM is an interesting buyer because it is a mammoth product and service vendor. I do not think of IBM as being a security product company, but I do think of them as an IT services company. It sounds like IBM will just push ISS products through its services group.

I wonder where this leaves other product/service companies? Looking at my MSSP post, I have a few thoughts on the remaining MSSPs. I am guessing that Counterpane and Cybertrust (TruSecure) would desperately like to be purchased. LURHQ is also independent and available. The remaining MSSPs tend to be smaller, or already part of large product/service companies (e.g., Symantec).

I know there are lots of MSSP readers of this blog. What do you think will happen?

As a footnote, I hope IBM eliminates ISS' motto (in the graphic). No one is ahead of the threat.

Senin, 24 April 2006

ENIRA Partners with Lancope

I've wanted to say something about ENIRA for several months now, but I've been under a non-disclosure agreement. This morning, however, I noticed this press release which quotes me.

What's the fuss? ENIRA is a nearby company (in northern Virginia) that sells a Network Response System. It's essentially an incident containment appliance that isolates hosts when directed to do so. It's neither an IDS nor firewall -- layer 3, 4, 7 (IPS), or otherwise. ENIRA learns your network topology by accessing infrastructure devices (switches, routers, firewalls, etc.) and implements a containment policy when told to isolate a host or segment.

The isolation mechanism makes the best possible choices, based on any policies and restrictions you have provided. It keeps track of its actions and acts like a "network engineer in a box." I think this is a great network-centric incident response product. Lancope is going to use it to implement short-term incident containment when StealthWatch identifies suspicious or malicious activity.

Jumat, 24 Maret 2006

Check Point Acquisition of Sourcefire Cancelled

According to Sourcefire's press release:

Sourcefire, Inc., the world leader in intrusion prevention, today announced that, with the consent of the US government, Sourcefire and Check Point Software Technologies have opted to withdraw their merger filing with the Committee on Foreign Investment in the United States (CFIUS). Sourcefire will continue to operate as the industry's largest private Intrusion Prevention System (IPS) vendor.

According to Check Point's press release:

The companies have determined that it would be more effective to create a customer focused business partnership. "We've decided to pursue alternative ways for Check Point and Sourcefire to partner in order to bring to market the most comprehensive security solutions," said Gil Shwed, Check Point's CEO.

Check Point and Sourcefire will continue to create and distribute the best security solutions in their respective spaces. They will work together on formulating a partnership strategy moving forward and will keep customers and partners updated as new plans are developed.


Their FAQ says this:

Is the Sourcefire acquisition cancelled?

We can still pursue the acquisition but at this point we will explore other opportunities. We will also focus on running our business and delivering the best solutions for customers.


Wow, it's cancelled -- despite what Check Point says. I thought this deal would go through, albeit with restrictions.

Kamis, 23 Februari 2006

Feds Delay Check Point Acquisition of Sourcefire

Based on a friend's tip, I found myself looking for this press release, which reads in part:

Check Point® Software Technologies Ltd. (NASDAQ: CHKP), the world leader in securing the Internet, received notice its pending acquisition of Sourcefire®, Inc. has moved into the investigative stage with the Committee on Foreign Investment in the United States ("CFIUS").

In order to clear the transaction with the United States Government, Check Point submitted two regulatory applications. Check Point received U.S. anti-trust approval and was advised that CFIUS would continue reviewing the application during a 45-day investigative period...

Pursuant to the Exon-Florio legislation, CFIUS reviews proposed foreign acquisitions of U.S. companies in order to protect national security while maintaining the credibility of the United States open investment policy. The Exon-Florio legislation provides for a 30-day review following notification of a potential acquisition. CFIUS has the option to extend the review period for an additional 45-day review (or "investigation").


That press release excerpt sounds fairly tame, but this article is more interesting:

CFIUS has 30 days in which to examine an acquisition. It can extend that period by 45 days for the purposes of investigation. This is exactly what has happened to Check Point. What's more, once the status of an examination becomes "investigative", the acquisition comes under the purview of none other than US President George W. Bush. At the end of the 45 days, CFIUS submits a report to the president, who must announce his decision within 15 days.

All in all then, taking into account the initial 30 day period, the 45 day investigation period, and the 15 days for the presidential decision, it can take 90 days from the initial examination of the application until the president informs Congress whether he chooses to block the deal or not. For Check Point, only the first 30 days have gone by, so that, theoretically, closure of the deal could be put back to the second quarter...

In the case of Check Point and Sourcefire, it is still not clear what the cause pf CFIUS's concern is. It is a fairly rare occurrence for it to choose to investigate such a low-value deal.


Another friend pointed me to this article:

Most foreign U.S. deals are approved after CFIUS completes an informal 30-day probe, but this transaction has raised the eyebrows of some of the panel members, leading to the lengthier examination.

"The fact that they launched a 45-day review means that some serious concerns are being raised," said a national security consultant who formerly worked at the Department of Defense.

Sources said CFIUS representatives from the Department of Defense and the Department of Homeland Security are worried that the deal gives critical computer network security technology to Israel. Sourcefire develops network security and information management systems for Defense Department agencies, in addition to private industry clients.


I'll keep my eye on this. I bet the deal will go through, with the government getting source code access to all Sourcefire products.

Rabu, 16 November 2005

Thoughts on CMP Acquisition of Black Hat

I just learned that CMP Media, publishers of IT magazines like Network Computing and IT Architect (formerly Network Magazine) just acquired Jeff Moss' Black Hat, Inc. for $10 million. I'm amazed that Black Hat went for that much. The organization may offer consulting, but it's mainly known for its conferences. Those conferences rely on instructors, none of whom are obligated to speak (as far as I know). Without any intellectual property, substantial workforce, or product lines, I'd say Black Hat did pretty well for itself!

I did not realize until now that CMP also owns the Computer Security Insitutute, who runs their own security conferences. The CSI conference is a strange beast. I wouldn't consider William Safire to be a "security expert," but there he is appearing as a keynote CSI speaker. Perhaps Black Hat is supposed to pull in another sort of demographic, one without as much gray hair?

Kamis, 13 Oktober 2005

Bejtlich Quotes in Sourcefire Acquisition Story

Eric B. Parizo mentioned me in his story Snort users fear future under Check Point. One of the quotes appears as follows:

Richard Bejtlich, principal with Washington, D.C.-based consultancy Tao Security, said many fail to realize just how expensive it is to support a product like Snort.

"I've been to Sourcefire, and I've seen how many people they have working on the product and on signatures," Bejtlich said. "They have what seems like millions and millions of racks of equipment. I was surprised they were able to continue with Snort as they did."


That should say "millions and millions of dollars of racks of equipment." I obviously haven't seen millions of racks of anything when I visit Sourcefire!

Also, I appear to have been demoted at my own company. I am not a "principle" at TaoSecurity. My boss must be upset with my performance! :)

Sabtu, 08 Oktober 2005

Thoughts on the Week's Security News

This was a busy week for me; I spent all week teaching (and all last week preparing) a private Network Security Operations class in California. I just flew back from LAX to Dulles this morning and I get on another plane tomorrow afternoon. I'm speaking in San Jose at a Cisco event, and then teaching a second private NSO class again next week.

I've been tracking all of the week's security news. Thank you to those who thought I may have missed something. I didn't want to commit any thoughts to the blog without taking some time to ponder various events. Obviously the biggest news of the week was Checkpoint's $225 million acquisition of Sourcefire.

In short, I didn't see that coming. I have doubts about the future of Snort being a free product, let alone open source. I don't see anyone making the case to the board of a publicly traded company that part of that company's work is going to be given away for free, especially after spending $225 million for it.

You may have seen how Checkpoint is treating users of the free version of Zonealarm, which was purchased by Checkpoint two years ago for $225 million. Sure, the basic Zonealarm firewall is still free, but Checkpoint will not provide a patch for a new security problem. Checkpoint claims the problem has low severity even though proof of concept code exists. To quote John LaCour, director of security services: "It is a theoretical attack that we don't see used in the real world." Great. That rationale has certainly stood the test of time (not).

However, I do not fault Sourcefire at all for being purchased. I never faulted them for the way they handled the new rules licensing, either. The amount of manpower and resources they devote to Snort is incredible, so I am happy to see them be rewarded. I am just not sure Checkpoint is the right fit, at least from where I stand. What are your thoughts?

Kamis, 14 Juli 2005

Verisign to Acquire iDEFENSE

The 45 survivors at iDEFENSE must be breathing a sigh of relief. Verisign will buy iDEFENSE for $40 million. That is $100 million less than the cost to acquire Guardent in December 2003. Verisign has over 3,500 employees according to its fact sheet, and it seems to be making ever bigger advances into the security market. I would be interested in hearing from any iDEFENSE insiders (anonymously here) what they think of this acquisition.

Senin, 16 Mei 2005

Launch of New TaoSecurity.com

I am happy to announce the redesign of TaoSecurity.com as the corporate home of TaoSecurity. In the coming days and weeks I will transition old, more personalized content to the www.bejtlich.net domain. TaoSecurity is open for business, and I look forward to helping you with your security consulting and training needs.

I have a ton of material to blog, including a wrap-up of BSDCan and some news items. I will be flying to San Francisco Tuesday and returning very early Thursday. Don't expect too many updates until I return home. Thank you!

Kamis, 10 Maret 2005

Visiting Sourcefire

Today I visited the Columbia, MD headquarters of Sourcefire with DC Snort Users Group founder Keith McCammon, pictured with me at left. We drove up from our Falls Church, VA office to meet with Sourcefire founder and Snort creator Marty Roesch. Sourcefire is housed in an Ikea-type building constructed to house optical networking start-ups during the dot-com craze. In addition to Sourcefire, Optical Capital Group Ventures and another company called Debt Shield share the space.

We started our conversation with Marty by discussing the new VRT Certified Rules License Agreement. Marty said that Sourcefire isn't a "nameless, faceless company. Real people work here." He demonstrated Sourcefire's commitment to the security community by mentioning the change to the Audit clause, previously reported here. Marty reported that many companies, several of which he was previously unaware, have reported interest in Snort Integrator licenses. As of this afternoon almost 2,000 people had already registered for the new rules system. The revenue collected from those who choose to subscribe and those who purchase Integrator Licenses will be reinvested in rule development. Sourcefire employees seven people on its Vulnerability Research Team to create and test rules. They include Judy Novak, who I had not seen for several years.

Besides helping to pay rule developer salaries, revenue from the new rules system will also help pay for the equipment Sourcefire uses to develop and test Snort. At right is a picture of one of the racks of networking and testing infrastructure Sourcefire owns. The racks holds $500,000 worth of Spirent Avalanche and Spirent SmartBits network traffic and load generation gear. When Sourcefire develops a new rule, they don't just run Tcpreplay to pass traffic and test Snort's ability to trigger an alert. (I'm not faulting Tcpreplay -- it's a great tool and I use it often. In fact, Aaron just announced the release of Tcpreplay 3.0beta1, with many new capabilities.)

Sourcefire tests that Snort is able to trigger an alert while watching a loaded network. I would like to see someone replicate this setup in their basement! In other words, it's not going to happen at anywhere near the same level of quality assurance. This is the problem I have with ventures like those of Demarc and the mysterious Mr. Alternative Ruleset. Users should always be able to create their own rules, as that is one of the strengths of an open system like Snort. However, they must be exceedingly careful not to cripple their IDS by writing poor rules.

At left is a picture of some of the racks containing servers Sourcefire uses to develop Snort and associated components. Marty said the company has over 26 racks with more than 300 servers. They maintain gear for every version of their appliance they've shipped. They also have target ranges and plenty of development systems. When Sourcefire develops a new rule, for example, they perform 6.8 million regression tests to ensure the new rule does not adversely affect the rest of the rule base. Sometimes these tests take up to four hours per change, even with the load distributed across multiple servers. Sourcefire takes great care to ensure that their rules will not cause Snort to waste excessive time processing packets. Marty told how a rule developed by an external Snort user once made such poor use of PCRE that it took Snort 3 seconds to process each packet!

After looking at Sourcefire's server room, we toured the workspace. Marty employees over 60 people in his Columbia, MD location at over 100 worldwide. In addition to meeting with Judy Novak, who works on the VRT, we also spoke with Snort rule uber-creator Brian Caswell. I mentioned that the Snort 2.3.1 ruleset had new rules not in the 2.3.0 distribution. bmc told me that 2.3.1 packaged all of the new rules up to the date of the new licensing structure, which was 7 March. We discussed having a future DC Snort Users Group meeting closer to Columbia, MD to accommodate the schedules of Marty and Brian. I was surprised to see so many people working on Snort -- you can see in the picture the row upon row of cubicles. There were two engineering meetings happening when I took the photo, so many desks are empty.

After touring the floor we spoke to Marty about the future of Sourcefire. He is excited about the new IS5800 appliance. "This will take the performance issue off the table, and leave detection technology as the key metric," Marty said. Previously companies like Sourcefire were criticized for not being able to keep up with offerings by Tipping Point. Marty reminded us that the ability to process packets per second was more important than a device's "Gigabit" rating. I saw the IS5800 myself, so it is not just marketing hype. I think it will be an amazing piece of gear for those who want to run Snort at speeds over 1 Gigabit.

Near the end of our visit Marty made some interesting points about market pressure on the security scene. He said Sourcefire felt the heat from Gartner's declaration that IDS is dead. (Incidentally, I reported in 2003 that the Meta Group countered Gartner's worldview by saying "network and host intrusion detection systems (IDS) [are] high on the shopping list" of big businesses. Unfortunately, their point of view died when Gartner acquired Meta for $162 million in December 2004.) The integration of the Snort-inline code gives stock Snort the capability to do IPS, which is currently the "hot topic" for security purchasers. Apparently security commentators and reporters want nothing to do with intrusion detection; it's all about IPS now. Unfortunately, we all know that prevention eventually fails.

Keith and I thanked Marty for spending nearly two hours with us. We drove down the street and met Tenable Security founder and CTO Ron Gula for lunch. Ron made some good comments concerning the state of security certifications when he heard I passed my CCNA exam. He said that no one can agree on how to approach the security problem. He divided the world into people that "do" firewalls, IDS, vulnerability scanning, code audits, and a few other categories. Each buys the product and/or service that fits their world view. No one can agree on a standardized methodology to secure a network. Some people think the CISSP meets this need, but anyone who has taken the test knows the CISSP fails miserably in this respect. I posted in 2003 some thoughts on good certification features, and I wrote in The Tao that the best aspect of the CISSP is its code of ethics.

At some point in the future I would like to spend some time at Tenable to get a better look at their operations as well. Thanks to both Marty and Ron for spending some time with us today!

Selasa, 22 Februari 2005

Lockheed Martin Acquires The Sytex Group

On Friday Lockheed Martin announced it is buying The Sytex Group for $462 million. Sytex's revenue for 2004 was $425 million, not much less than the asking price. It shows that service companies sell for much less than product companies. According to the cited story, about 85 percent of Sytex’s revenue comes from the US Department of Defense. I guess those contracts are not worth as much in forward-looking terms as one might expect?

Minggu, 13 Februari 2005

Thoughts on MCI Acquisition of NetSec

I only recently learned that telecom giant MCI bought managed security services provider NetSec for $105 million. Other telecom companies might want to look at Lisa Phifer's Managed Security Service Provider Survey or Adam Stone's In MSSPs We Trust for acquisition candidates. I expect acquisitions to continue, as there are between one and two dozen small MSSPs available. There are also people like myself who know how to build MSSPs from the ground up (hint hint). :)

Update: It must be confusing to work for NetSec. One minute you're working for MCI, the next you're working for Verizon!

Kamis, 10 Februari 2005

Another Foundstone Spin-Off: Security Compass

I was happy to learn that another friend and ex-Foundstone colleague, Nish Bhalla, has started his own consulting company: Security Compass. Nish most recently contributed to the new book Buffer Overflow Attacks, which I plan to read. Nish is an expert on Web and application security, so if you need a customized, in-depth assessment of those services give him a call!